6.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.3 High
AI Score
Confidence
Low
0.476 Medium
EPSS
Percentile
97.5%
Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to cause denial of service, execute arbitrary code.
Below is a complete list of vulnerabilities:
CVE-2022-23267 critical
CVE-2022-30129 critical
CVE-2022-29117 critical
CVE-2022-29148 critical
CVE-2022-30130 warning
CVE-2022-29145 critical
Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)
Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.
Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.
support.microsoft.com/kb/5013837
support.microsoft.com/kb/5013838
support.microsoft.com/kb/5013839
support.microsoft.com/kb/5013840
support.microsoft.com/kb/5013870
support.microsoft.com/kb/5013871
support.microsoft.com/kb/5013872
support.microsoft.com/kb/5013873
support.microsoft.com/kb/5014326
support.microsoft.com/kb/5014329
support.microsoft.com/kb/5014330
support.microsoft.com/kb/5021243
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23267
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29117
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29145
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29148
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30129
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30130
statistics.securelist.com/
threats.kaspersky.com/en/product/Microsoft-.NET-Framework/
threats.kaspersky.com/en/product/Microsoft-Visual-Studio/
6.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.3 High
AI Score
Confidence
Low
0.476 Medium
EPSS
Percentile
97.5%